The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to establish national standards for protecting the privacy, security, and confidentiality of individuals’ health information. As part of HIPAA compliance, covered entities and business associates are required to implement certain administrative, physical, and technical safeguards to protect patients’ health information. One critical aspect of HIPAA compliance is completing HIPAA compliance forms.
This webpage provides an overview of the most important forms that organizations need to complete to ensure HIPAA compliance.
A HIPAA compliance checklist helps healthcare organizations review the policies, procedures, safeguards, and training they use to protect protected health information (PHI). Use this checklist to review key areas of HIPAA compliance, including the Privacy Rule, Security Rule, Breach Notification Rule, patient rights, HIPAA authorizations, workforce training, and business associates.
HIPAA compliance is an ongoing process. Organizations should regularly review their policies, identify risks, update safeguards, train their workforce, and document compliance activities.
Notice of Privacy Practices (NPP) is a form that covered entities must provide to their patients upon joining and whenever the policy changes. The NPP informs patients about how their health information will be used and disclosed, as well as the patient’s rights with respect to their health information. The NPP must include details such as the types of uses and disclosures that the covered entity can make, the patient’s rights to access and amend their health information, and the covered entity’s policies and procedures regarding using their health information.
The HIPAA Privacy Policy is a written document that outlines the covered entity’s policies and procedures for protecting patients’ privacy rights. It should include how the covered entity uses, discloses, and safeguards protected health information (PHI) and patients’ rights to access and amend their PHI. The Privacy Policy should be reviewed and updated regularly to ensure that it reflects any changes to HIPAA regulations or the covered entity’s practices. This applies to all healthcare providers including healthcare couriers.
Use this HIPAA compliance checklist to review the major areas of your organization's HIPAA program.
☐ Identify the protected health information (PHI) your organization handles.
☐ Establish written privacy policies and procedures.
☐ Define who can access and disclose PHI.
☐ Review permitted uses and disclosures of PHI.
☐ Apply the minimum necessary standard when applicable.
☐ Provide a Notice of Privacy Practices when required.
☐ Establish procedures for patient requests to access PHI.
☐ Establish procedures for requesting amendments to PHI.
☐ Establish procedures for restrictions and confidential communications.
☐ Establish procedures for HIPAA authorizations.
☐ Establish a process for handling privacy complaints.
☐ Train workforce members on HIPAA privacy policies.
The HIPAA Security checklist comprehensively reviews the covered entity’s administrative, physical, and technical safeguards to protect PHI. The assessment should identify potential risks to the confidentiality, integrity, and availability of PHI, as well as any vulnerabilities that hackers or unauthorized individuals could exploit. The Security Risk Assessment should be performed annually or whenever significant changes occur in the covered entity’s technology, processes, or personnel.
☐ Complete a security risk analysis.
☐ Identify threats and vulnerabilities affecting electronic PHI (ePHI).
☐ Document security risks and determine how they will be addressed.
☐ Establish written security policies and procedures.
☐ Assign responsibility for HIPAA security.
☐ Control workforce access to ePHI.
☐ Implement appropriate user authentication.
☐ Protect workstations and devices that access ePHI.
☐ Use appropriate technical safeguards to protect ePHI.
☐ Review audit logs and system activity when appropriate.
☐ Establish procedures for security incidents.
☐ Maintain a contingency plan for emergencies and system disruptions.
☐ Review and update security measures regularly.
Implementing a patient's right to access their PHI is an important part of HIPAA compliance. Covered entities must provide patients with timely access to the information they request in a manner that is convenient and cost-effective. Patients should be able to view, download, or receive copies of their PHI upon request. The covered entity should also provide the patient with an explanation of any codes or abbreviations used in the PHI.
HIPAA compliance forms and checklists are critical components of a covered entity’s compliance program. By completing these forms and checklists, covered entities can ensure that they have implemented the necessary administrative, physical, and technical safeguards to protect PHI and comply with HIPAA regulations. Covered entities should regularly review and update their HIPAA compliance forms and checklists to reflect changes in HIPAA regulations or the covered entity’s practices.
A comprehensive checklist should address Privacy Rule requirements, Security Rule safeguards, breach notification procedures, PHI protection, patient rights, HIPAA authorizations, workforce training, business associates, risk analysis, and documentation.
The five HIPAA Administrative Simplification rules are the Privacy Rule, Security Rule, Transactions and Code Sets Rule, Unique Identifiers Rule, and Enforcement Rule.
A HIPAA Privacy Rule checklist helps organizations review how they protect PHI and manage permitted uses, disclosures, patient rights, authorizations, privacy policies, and complaints.
A HIPAA authorization checklist helps organizations review whether an authorization contains the information required by the HIPAA Privacy Rule, such as the information to be disclosed, the parties involved, the purpose, expiration information, and required signature.
A protected health information checklist helps organizations identify the PHI they handle and review the safeguards used to protect it from unauthorized access, use, disclosure, alteration, or loss.
No. HIPAA obligations depend on the type of organization, the information it handles, its activities, and its role under HIPAA. Organizations should also consider applicable state and other federal requirements.
HIPAA compliance should be reviewed on an ongoing basis rather than treated as a one-time task. Organizations should review their policies, safeguards, risks, workforce access, vendors, and incident procedures regularly and update them when circumstances change.
No. A checklist is a review tool, not a guarantee of compliance. Organizations need appropriate policies, procedures, safeguards, training, documentation, and ongoing risk management based on their specific operations.
A HIPAA compliance checklist is a useful starting point, but proper training helps employees and organizations understand how HIPAA applies to their specific responsibilities. Completing role-specific HIPAA training can help your team recognize privacy and security risks, protect PHI, and follow appropriate procedures when handling health information.
If you need HIPAA training for your role or organization, CPR Select offers role-specific HIPAA courses for:
Choose the course that matches your role and responsibilities to learn how HIPAA applies to the information you handle and the situations you encounter at work.
Ready to complete your HIPAA training? Explore CPR Select's HIPAA courses and choose the training that fits your role.